VulnerabilityModified
CVE-2012-1410
Multiple cross-site scripting (XSS) vulnerabilities in the History Window implementation in Kadu 0.9.0 through 0.11.0 allow remote attackers to inject arbitrary web script or HTML via a crafted (1) SMS message, (2) presence message, or (3) status…
MEDIUM 4.3EPSS 2.55%
Does this matter?
Lower severity and a low EPSS score (2.55%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the History Window implementation in Kadu 0.9.0 through 0.11.0 allow remote attackers to inject arbitrary web script or HTML via a crafted (1) SMS message, (2) presence message, or (3) status description.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.55% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- kadu/kadu
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2012/02/27/26
- http://www.openwall.com/lists/oss-security/2012/02/27/3Patch
- https://bugzilla.novell.com/show_bug.cgi?id=749036Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=797777Patch
- https://gitorious.org/kadu/kadu/commit/91772e46541e22cbc2c7bf41a1a9798c2a58f6d6Patch
- https://gitorious.org/kadu/kadu/commit/94e7479617d78a1649a0763960edade7ad09a0d0Patch
- https://gitorious.org/kadu/kadu/commit/e9506be6d3dcdd408fdf83d8eb82416c9b798c84Exploit, Patch
- https://gitorious.org/kadu/kadu/commit/ebe3674cf0f3aa9b36308c06e19cb293cc790b52Exploit, Patch
- http://www.openwall.com/lists/oss-security/2012/02/27/26
- http://www.openwall.com/lists/oss-security/2012/02/27/3Patch
- https://bugzilla.novell.com/show_bug.cgi?id=749036Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=797777Patch
- https://gitorious.org/kadu/kadu/commit/91772e46541e22cbc2c7bf41a1a9798c2a58f6d6Patch
- https://gitorious.org/kadu/kadu/commit/94e7479617d78a1649a0763960edade7ad09a0d0Patch
- https://gitorious.org/kadu/kadu/commit/e9506be6d3dcdd408fdf83d8eb82416c9b798c84Exploit, Patch
- https://gitorious.org/kadu/kadu/commit/ebe3674cf0f3aa9b36308c06e19cb293cc790b52Exploit, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.